Lucene search

K
wpvulndbKaushalendra DubeyWPVDB-ID:D5CE4B8A-9AA5-4DF8-B521-C2105990A87E
HistoryApr 25, 2022 - 12:00 a.m.

Gmedia Photo Gallery < 1.20.0 - Admin+ Stored Cross-Site Scripting

2022-04-2500:00:00
Kaushalendra Dubey
wpscan.com
10

0.001 Low

EPSS

Percentile

24.8%

The plugin does not sanitise and escape the Album’s name before outputting it in pages/posts with a media embed, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered-html capability is disallowed

PoC

https://youtu.be/kTMg65teTvU Create an Album with the following payload as Name: test"> Add a media via the “Add/Import files” menu and select the album created above The XSS will be triggered when viewing the media post

CPENameOperatorVersion
grand-medialt1.20.0

0.001 Low

EPSS

Percentile

24.8%

Related for WPVDB-ID:D5CE4B8A-9AA5-4DF8-B521-C2105990A87E